Back to skill

Security audit

Freqtrade US Setup

Security checks for vulnerabilities and agentic risk

Overview

This is a mostly coherent Freqtrade setup guide, but it handles real trading credentials and tells users to run mutable upstream Docker code with some unclear credential-storage guidance.

Review before installing. Use only a pinned, reviewed Freqtrade release or image digest, keep Kraken withdrawal permission disabled, start in dry-run mode, and store real API keys only in a gitignored secret file or a secrets manager, not directly in docker-compose.yml or config files.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
references/security-checklist.md:49
Finding

Kraken API Credentials Are Embedded Directly in Docker Compose Configuration

Content
View full analysis
Remediation
View remediation

T03 · Remote Payload Retrieval and Execution

Warning
Location
SKILL.md:34
Finding

Mutable Remote Freqtrade Repository Is Retrieved and Executed Without Version Pinning

Content
View full analysis
Remediation
View remediation
--depth 1 \ https://github.com/freqtrade/freqtrade.git cd freqtrade git rev-parse HEAD ``` - For stronger immutability, document the expected commit hash and verify that `git rev-parse HEAD` matches it before execution. - Verify signed release tags or commits where upstream signing is available. - Pin all container images by immutable digest rather than relying only on mutable tags: ```yaml image: repository/image@sha256: ``` - Review the downloaded Compose file before running it, especially its volume mounts, environment variables, capabilities, privileged mode, host networking, and Docker socket access. - Document a controlled upgrade process in which new releases and image digests are reviewed before updating the pinned values. - Run the container with least privilege, read-only filesystems where practical, minimal mounts, and only the network and credentials required for the task. ]]>
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (7)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 70)May include surrounding context.

Add to .gitignore immediately:

bash
echo ".env" >> .gitignore

In user_data/config.json, leave the exchange key and secret as empty strings — Freqtrade will populate them from the env vars automatically:

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/security-checklist.md (reported line 41)May include surrounding context.

📦 Key Storage

Step 1: .env File (Local Machine)

bash
# Good ✅

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/security-checklist.md (reported line 61)May include surrounding context.

📦 Key Storage

Step 1: .env File (Local Machine)

bash
# Good ✅

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/security-checklist.md (reported line 62)May include surrounding context.

📦 Key Storage

Step 1: .env File (Local Machine)

bash
# Good ✅

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/security-checklist.md (reported line 120)May include surrounding context.

📦 Key Storage

Step 1: .env File (Local Machine)

bash
# Good ✅

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/security-checklist.md (reported line 121)May include surrounding context.

📦 Key Storage

Step 1: .env File (Local Machine)

bash
# Good ✅

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/security-checklist.md (reported line 121)May include surrounding context.

On Kraken: disable + regenerate the API key immediately

On your machine:

rm .env # Delete the old one

Create new .env with new keys from Kraken

text

### Running Freqtrade Safely

Static analysis

No suspicious patterns detected.